Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Deutsche Bank breached via supplier as Unsafe gang leaks data

Ransomnews Research TeamBy Ransomnews Research TeamJuly 17, 2026Updated:July 18, 2026No Comments4 Mins Read76 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Deutsche Bank breached via supplier as Unsafe gang leaks data, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A ransomware group calling itself Unsafe posted samples of Deutsche Bank employee data in early July 2026, drawn from a third-party marketing and incentive platform the bank uses. Deutsche Bank confirmed a supplier breach but said “there is no indication that Deutsche Bank’s internal systems or networks were affected.” Researchers who reviewed the leaked screenshots, which include employee emails, password hashes, and addresses, assessed them as appearing legitimate. The incident is a live test of third-party risk rules under the EU’s DORA regulation.

// KEY FACTS

Threat actor
Unsafe
Victim
Deutsche Bank (via third-party platform provider) · Banking and finance · Germany
Timeline
Attack: 2026-07  ·  Disclosed: 2026-07-08
Data claimed
Sample sets; full volume undisclosed · Employee emails, password hashes, physical addresses, internal database records
Ransom status
No public demand documented
Verification
Bank confirmed a third-party breach and denied internal compromise; researchers assessed leaked samples as appearing legitimate

What did the Unsafe group claim?

Unsafe posted screenshots purporting to show Deutsche Bank employee records: corporate email addresses, password hashes, physical addresses, and internal database rows. The group continued releasing samples through the week. Cybernews researchers who examined the material said it appeared legitimate, though they cautioned it was “not possible to determine whether customer data is included.” No specific ransom figure has been made public.

What did Deutsche Bank say?

The bank confirmed a breach at a third-party provider, a marketing and incentive platform, and drew a firm line around its own estate: no indication that internal systems or networks were affected. That is a plausible and common outcome. Enterprises push large volumes of employee and campaign data to SaaS vendors, and a vendor compromise can expose that data without any attacker ever touching the enterprise network. The gap worth watching is between the bank’s confident denial and the researchers’ read that the samples look real.

DEUTSCHE BANK // WHERE THE DATA LEAKED DEUTSCHE BANK internal network NO internal compromise → pushes data 3RD-PARTY SAAS marketing platform BREACHED → exfiltrated UNSAFE leak-site samples EXPOSED IN SAMPLES – Employee emails – Password hashes – Physical addresses – Internal database records Customer data inclusion: unconfirmed | First samples posted ~Jul 8, 2026

Why this is a DORA stress test

The EU’s Digital Operational Resilience Act makes financial firms accountable for the ICT risk their third parties carry. A supplier breach exposing employee data is precisely the scenario DORA was written for: the bank’s own controls held, but its vendor’s did not, and the reputational and regulatory exposure still lands on the bank. How Deutsche Bank documents, reports, and remediates this vendor incident is the kind of case that will shape how European regulators read third-party obligations in practice.

What affected employees should do

Any Deutsche Bank employee whose corporate credentials appear in the samples should assume the password hash is compromised and treat the account as needing an immediate reset, ideally with phishing-resistant multi-factor authentication. Password hashes can be cracked offline, so the exposure is not neutralized by the vendor pulling the data. Reused passwords elsewhere should be rotated too, and staff should watch for targeted phishing that uses the leaked internal details for credibility. Track the Ransomtracker live feed for any escalation.

Frequently asked questions

Was Deutsche Bank’s own network hacked?

The bank says no. It confirmed a breach at a third-party marketing and incentive platform and stated there is no indication its internal systems or networks were affected.

Who is the Unsafe ransomware group?

Unsafe is the group that posted the Deutsche Bank employee data samples. It is a lesser-known extortion actor, and details about its wider operations remain limited.

What data was exposed?

The leaked samples include employee emails, password hashes, physical addresses, and internal database records. Researchers could not confirm whether any customer data is included.

Is customer banking data affected?

There is no confirmation that customer data was exposed. The available samples relate to employee and internal platform records, not customer banking systems.

What is DORA and why does it matter here?

DORA is the EU’s Digital Operational Resilience Act, which holds financial firms responsible for the ICT risk carried by their third-party suppliers. A vendor breach like this is exactly the third-party scenario the regulation governs.

Sources and further reading

  • Cybernews: Deutsche Bank ransomware data breach (July 7-8, 2026)
  • Computing: Deutsche Bank probes supplier cyber incident (July 2026)
  • teiss: Deutsche Bank faces new breach claims (July 2026)
  • Ransomnews Ransomtracker: live ransomware victim feed
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleScattered Spider duo jailed 5.5 years over £29M TfL hack
Next Article LockBit 5.0: the comeback nobody wanted
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.